Skip to main content

SSH into a Synology or QNAP NAS from your Mac

A shell for the jobs the web interface hides, SFTP for moving files, and the admin page reached through SSH instead of an open port.

By Lucas Russo, developer of SSHive · Updated

A NAS runs a trimmed-down system (DSM on Synology, QTS on QNAP, TrueNAS, Unraid) and offers SSH for the jobs its web interface does not cover: checking df -h, editing a Docker Compose file, restarting a package that hangs, reading a log. From a Mac the routine is short: a shell, a file transfer now and then, and the admin page when you are away from home. SSHive keeps one profile per NAS, with the SFTP file manager next to the terminal in the same tab. Drag files in from Finder to upload them, or open a text file in the built-in editor, change it on the NAS and save with ⌘S.

Turn on SSH, and SFTP, in DSM

In DSM, open Control Panel > Terminal & SNMP > Terminal and tick Enable SSH service. Synology suggests moving it off the default port 22; whatever you pick goes in the profile. Only accounts in the administrators group can log in over SSH, and sudo -i gives you root when a task needs it. SFTP is a separate service in DSM, under Control Panel > File Services > FTP, in the SFTP section: tick Enable SFTP service if you want the file manager as well as the terminal. Then create the profile in SSHive with the NAS address, the port and that administrator account, and move to a key once the password login works.

The DSM web interface through a tunnel

DSM listens on 5000 (HTTP) and 5001 (HTTPS). Rather than forwarding those ports on your router, add a local tunnel to the NAS profile: local port 5001, remote host localhost, remote port 5001. Connect, then open https://localhost:5001; the browser may warn that the certificate was not issued for localhost, which is expected. The same approach works for QTS on QNAP (8080 by default) and for TrueNAS or Unraid on 80 or 443. From outside your home, the SSH port itself still has to be reachable: through a VPN such as Tailscale or WireGuard, or a forwarded port that only accepts keys.

What is free here, and what needs Pro

SSH, the SFTP file manager and one local tunnel on the profile, enough for DSM, are free, as are 5 profiles. The free version caps uploads at 10 MB per file: plenty for configs, scripts and documents, too small for videos or disk images. SSHive Pro lifts that cap and adds more tunnels, remote tunnels and broadcast for several NAS units, for a one-time $12.99.

Frequently asked questions

Why is SFTP to my NAS slower than a file share?+
SFTP encrypts everything it sends, and on a NAS with a modest ARM processor the encryption, not the network, often sets the pace; Synology's own help page warns that encryption lowers transfer speed and uses more system resources. For moving a whole photo library on your home network, the NAS's SMB share is quicker. SFTP is the right tool for the file you need now, and for reaching the NAS securely from outside.
Can SSHive replace the Synology Drive client?+
No. Synology Drive syncs folders in the background and resolves conflicts; SFTP in SSHive is for deliberate file operations. Use both: Drive for what should stay in sync, SSHive for admin work and one-off transfers.
Can I browse the NAS from my iPhone?+
Yes. The iPhone and iPad SFTP app browses the NAS over SFTP and opens an SSH shell to it, with the same free limits, and one Pro purchase covers the Mac and the iPhone.

Try SSHive Free for macOS

Get the all-in-one SSH, SFTP, RDP and VNC client for Mac. Free download, no signup required.